Financial Integrity Monitor

Ireland IE

Domains (D1–D6)
6
Sources
8
Role actions
8
Horizon <90d
5
Jurisdiction profile
CleanTier ARisk: IncreasingMixed

Ireland's AML/CFT regime rests on the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010-2021 (5AMLD-transposing), with the Central Bank of Ireland as lead AML/CFT supervisor for financial institutions and VASPs, the FIU embedded in the Garda National Economic Crime Bureau, and the CRO/RBO handling corporate and beneficial-ownership registration.

MoreAs an EU member and international financial centre, Ireland will absorb the AMLR/AMLA package and MiCA in parallel.

Key deficiencies
  • EU Commission-flagged inadequacy and inaccessibility of the beneficial ownership register of trusts under 4th/5th AMLD transposition
  • Persistently low money-laundering conviction rate after full trial despite a sound legislative framework, per FATF's 2017 MER, unresolved as of the 2022 follow-up
  • Structural exposure of Ireland's extractive/commodity export sector (Aughinish Alumina refinery) as an unintended conduit into Russian sanctioned arms supply chains
  • Complex, non-transparent fund and securitisation structures (QIAIFs, Section 110 SPVs) that increase third-party-reliance CDD vulnerabilities in the funds sector
Recent developments (18m)
  • OCCRP investigation (published ~March 2026) revealing Aughinish Alumina (Rusal-owned, Co. Limerick) alumina exports reaching Russian smelters supplying EU-sanctioned arms manufacturers, triggering an Irish government probe and Oireachtas debate
  • President Zelenskyy's Dublin visit at the start of Ireland's EU Council presidency calling for closure of the Aughinish supply chain and EU sanctions loopholes
  • FATF confirmed Ireland absent from both the February 2026 and June 2026 Jurisdictions Under Increased Monitoring lists
  • Continued EU Commission pressure via infringement procedure over Ireland's trust beneficial-ownership register adequacy, opened April 2024 and unresolved
  • Ireland positioned among early-mover EU states (with France, Luxembourg, Lithuania) already implementing MiCA CASP requirements ahead of the July 2026 mandatory transition deadline
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The Office of Financial Sanctions Implementation in the United Kingdom has applied Regulation 17A(2) of the Russia (Sanctions) (EU Exit) Regulations 2019 to eighteen crypto-asset exchanges, including HTX (formerly Huobi), for the first time on record, alleging that more than 1.5 billion US dollars was channelled to Russian counterparties through this exchange network. The finding is held at an assessed confidence level rather than confirmed: it rests on a single Tier-3 secondary report, and the primary OFSI notice needed to verify the designation has not yet been retrieved. The structural significance of the action does not depend only on the dollar figure alleged. What is analytically notable is the mechanism at work: a UK autonomous sanctions instrument applied directly against virtual-asset-service-provider infrastructure rather than against designated persons who merely use that infrastructure downstream. If the primary notice confirms the reported scope, this would mark a genuine widening of the enforcement toolkit available to OFSI, extending the sanctions-evasion architecture built around Russia into virtual-asset rails for the first time.

Running alongside this, on firmer sourcing, the US Treasury Office of Foreign Assets Control designated two Mexican nationals and nine entities tied to the CJNG fuel-smuggling network known as huachicol fiscal, while the Financial Crimes Enforcement Network issued a parallel supplemental alert addressing the same typology along the southern US border. This action is held at high confidence and rests on a primary Treasury press release; it explicitly builds on a prior suspicious-activity-report total exceeding 7 billion US dollars, indicating sustained monitoring of this cartel-finance corridor rather than a newly discovered scheme. Read together, the OFSI action and the OFAC/FinCEN action mark the sanctions-architecture domain as escalating this cycle: designation practice extends into virtual-asset infrastructure on one side of the Atlantic while trade-based-money-laundering enforcement against cartel fuel-tax evasion deepens on the other.

Other Developments

Ireland published a third National Risk Assessment on money laundering, terrorist financing, and proliferation financing, together with a 30-Point AML/CFT/CPF Action Plan. The plan addresses interconnection of the beneficial-ownership register with the wider EU BORIS system and additional data-verification powers for registrars under sixth-Directive transposition. The posture is assessed as structurally improving, though implementation lags the stated target: transposing legislation for the relevant AMLD6/AMLR provisions had not yet been drafted as of the most recent professional-services assessment consulted this cycle.

The Central Bank of Ireland fined Coinbase Europe Limited 21,464,734 euro for anti-money-laundering and counter-terrorist-financing transaction-monitoring failures spanning 2021 through 2025, one of the largest crypto-sector AML enforcement actions taken by any EU national competent authority to date.

The national grandfathering window allowing VASPs registered in Ireland to transition to CASP status under MiCA Article 143(3) closes on 1 July 2026, with mandatory Central Bank of Ireland portal submission required from 2 April 2026. Sources consulted this cycle conflict on whether Ireland compressed the standard eighteen-month EU-wide transition window, and this discrepancy remains unresolved.

The Governor of the National Bank of Cambodia, Chea Serey, issued a public warning that the country risks a third FATF grey-list placement, citing casino- and scam-centre-linked laundering. The claim is corroborated across multiple Tier-3 and Tier-4 sources but lacks Tier-1 confirmation of an actual re-listing decision this cycle.

Laos remains confirmed on the FATF grey list, a status in place since 21 February 2025, with the Kings Romans Casino in the Golden Triangle Special Economic Zone persisting as a trade-based-money-laundering hub. The government of Laos holds a 20 percent equity stake in the casino operator, an arrangement that gives the finding a direct state-capture character.

At its June 2026 Plenary, FATF added Bosnia and Herzegovina and Iraq to the grey list, following the addition of Kuwait and Papua New Guinea at the February 2026 Plenary. Giles Thomson of the United Kingdom becomes the incoming FATF President from 1 July 2026.

Colombia remains in the enhanced follow-up process administered by GAFILAT, with no fresh signal beyond standing status this cycle.

Cross-Monitor Connections

The CJNG fuel-smuggling architecture carries direct commodity-flow relevance for the energy-fraud remit of ERM, given that the huachicol fiscal typology depends structurally on fuel-tax-evasion infrastructure rather than on financial mechanics alone. The Golden Triangle Special Economic Zone dynamic in Laos, in which a 20 percent government equity stake sits inside a casino operator already sanctioned, is assessed as a clean state-capture case for the kleptocratic-architecture remit of WDM. The National Risk Assessment published by Ireland, its transposition posture under the sixth Directive, and the EU-wide MiCA CASP transition are jointly relevant to the EU-regulatory-gap tracking conducted by ESA, since both instruments bear on the consistency of supervisory build-out across the bloc. The novel crypto-exchange designation mechanism applied by OFSI, together with the continuing sanctions-evasion architecture built around Russia, carries direct macro and sanctions-regime relevance for GMM, though the propagation of this specific vector should be treated as provisional pending primary-source verification.

Outlook

The EU AML Package continues to move through a staged implementation sequence. The directly applicable AML Regulation is assessed for full application in the third quarter of 2027, the beneficial-ownership transposition deadline under the sixth Directive falls in the third quarter of 2026, and the direct-supervision perimeter of the Anti-Money Laundering Authority for high-risk obliged entities does not activate until the first quarter of 2028, a sequencing that leaves a multi-year gap between the operational start of the Authority in 2025 and its substantive supervisory reach. The transposition timeline in Ireland is the nearest pressure point on this sequence: the gap between the third-quarter-2026 beneficial-ownership deadline and transposing legislation not yet drafted is a watch item for the coming cycle. On sanctions architecture, the crypto-exchange designation applied by OFSI requires primary-source verification before its structural significance can be assessed beyond the current tier, while the FATF grey-list expansion and the public re-listing risk warning issued in Cambodia both signal continuing pressure on enabler-jurisdiction postures across Southeast Asia and the Balkans. No substantive finding was located this cycle for conflict finance and extractive-industry integrity, a gap logged explicitly rather than filled with unsupported material, alongside thin coverage of jurisdictions in Sub-Saharan Africa and Central Asia.

weekly_brief_draft · JID IE
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The defining development in the sanctions-architecture domain this cycle is the first-ever application by OFSI of Regulation 17A(2) of the Russia (Sanctions) (EU Exit) Regulations 2019 against virtual-asset-service-provider infrastructure: eighteen crypto-asset exchanges, including HTX (formerly Huobi), designated on allegations that more than 1.5 billion US dollars was channelled to Russian counterparties through the network. The finding is held at an assessed confidence level because it currently rests on a single Tier-3 secondary report and has not yet been matched against a primary OFSI notice. That sourcing caveat matters for how the finding should be weighted in any downstream propagation, but it does not diminish the structural question the action raises. On current information, this is the first instance of a UK autonomous sanctions instrument being applied directly to exchange infrastructure rather than to the designated persons who use that infrastructure. If the primary notice confirms the reported scope, the action would mark a genuine widening of the enforcement toolkit available under the UK Russia sanctions regime, moving OFSI practice toward the kind of infrastructure-level designation that OFAC has used with greater frequency against Russian-linked entities.

A second, better-sourced escalation runs alongside this in the same domain. OFAC designated two Mexican nationals and nine entities connected to the CJNG fuel-smuggling network known as huachicol fiscal, and FinCEN issued a parallel supplemental alert addressing the same typology along the southern US border. This action rests on a primary US Treasury press release and carries high confidence. It is explicitly framed by FinCEN as building on a prior suspicious-activity-report total exceeding 7 billion US dollars, which indicates that this typology has been under sustained monitoring rather than newly identified this cycle. The designation extends sanctions authority into a domain that sits at the intersection of trade-based money laundering and sanctions enforcement, illustrating how US sanctions authority and Bank Secrecy Act reporting requirements are increasingly fused against a single criminal-finance architecture rather than deployed separately.

The confidence architecture across these two findings is instructive in its own right. The CJNG designations rest on Tier-1 primary sourcing and reach high confidence; the OFSI crypto-exchange action rests on Tier-3 secondary sourcing and is held at assessed confidence pending verification. This is not a defect specific to this research cycle so much as a structural feature of how different sanctions authorities communicate: OFAC publishes granular, near-real-time designation notices, while OFSI notice practice has historically lagged in public accessibility, and this cycle reproduces that pattern rather than departing from it.

The grey-list additions of Bosnia and Herzegovina and Iraq at the June 2026 FATF Plenary, following the February 2026 additions of Kuwait and Papua New Guinea, sit adjacent to the sanctions-architecture domain rather than inside its core. Grey-listing functions as a soft, enhanced-due-diligence instrument rather than a designation regime of the OFAC or OFSI type, but the pace of four additions across two Plenary cycles is itself a data point on FATF listing tempo under the incoming presidency of Giles Thomson of the United Kingdom, who takes office from 1 July 2026.

A standing tracker on sanctions-regime divergence between the United Kingdom, the United States, and the European Union remains at incremental-development status this cycle. The first-time use by OFSI of an autonomous designation mechanism against crypto-exchange infrastructure illustrates continuing divergence in designation mechanics between the post-exit UK sanctions regime and the US OFAC framework, though this specific observation is held at only possible confidence, since it depends on the same unverified primary sourcing as the underlying designation.

Outlook

The immediate item for verification next cycle is the primary OFSI notice confirming the Regulation 17A(2) crypto-exchange designation; without it, the finding cannot be upgraded past assessed confidence, and this gap is logged explicitly as an open item rather than treated as resolved. If confirmed, the precedent value is substantial: VASP-targeted designation under an autonomous UK sanctions instrument would give OFSI an enforcement tool set that more closely resembles US and EU sanctions practice, with implications for how exchanges assess UK sanctions-compliance exposure relative to their US and EU exposure. On the cartel-finance side, the scale of the prior suspicious-activity-report total behind the CJNG designations suggests further action against correspondent-banking or trade-finance intermediaries servicing this network is plausible, though this is offered as an orientation for continued monitoring rather than a forecast. The FATF grey-list additions merit tracking as a possible acceleration in listing tempo under the incoming UK presidency, though the sample of Plenary cycles available for comparison remains too short to characterise this confidently as an established trend rather than ordinary listing variance.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

Across the cycles tracked so far, the sanctions-architecture domain for the Financial Integrity Monitor opens on a baseline in which two independent enforcement architectures are escalating in different directions at once. On the UK side, OFSI has, for the first time on available information, applied Regulation 17A(2) of the Russia (Sanctions) (EU Exit) Regulations 2019 directly against virtual-asset-service-provider infrastructure: eighteen crypto-asset exchanges, including HTX, designated on allegations of more than 1.5 billion US dollars channelled to Russian counterparties. This remains, through the current cycle, an assessed rather than confirmed finding, since it rests on a single Tier-3 secondary report and the primary OFSI notice needed to establish the designation with certainty has not yet been retrieved. The structural reading that has held since the baseline cycle is unchanged: this is the first instance on record of a UK autonomous sanctions instrument being turned on exchange infrastructure itself rather than on the individuals or entities who use that infrastructure downstream, and if the primary source confirms the reported scope, it represents a genuine widening of the OFSI enforcement toolkit toward the infrastructure-level designation model more commonly associated with OFAC.

On the US side, the CJNG fuel-smuggling network known as huachicol fiscal has become a recurring node of attention, with OFAC designating two Mexican nationals and nine entities and FinCEN issuing a parallel supplemental alert. This action, unlike the OFSI designation, rests on primary Treasury sourcing and is held at high confidence throughout. FinCEN has explicitly framed the current action as building on a prior suspicious-activity-report total exceeding 7 billion US dollars, establishing that this typology has been under sustained monitoring across multiple cycles rather than surfacing as an isolated event. Read cumulatively, the huachicol fiscal designations illustrate a pattern in which US sanctions authority and Bank Secrecy Act reporting requirements are progressively fused against a single cartel-finance architecture, extending from initial SAR-driven detection toward direct Treasury designation of the individuals and entities operating the laundering network.

The asymmetry in sourcing quality between these two tracks, Tier-1 primary confirmation for the CJNG designations against Tier-3 secondary reporting for the OFSI crypto-exchange action, has persisted since the domain was first tracked and remains the single most important calibration point for any reader assessing this domain. It reflects a structural feature of how the two sanctions authorities communicate publicly rather than a defect of this research cycle specifically: OFAC issues granular near-real-time notices as a matter of routine practice, while OFSI notice publication has historically lagged in public accessibility. Until a primary OFSI notice is retrieved and matched against the reported eighteen-exchange designation, the crypto-exchange finding should continue to be treated as provisional in any cross-monitor propagation, particularly toward GMM and the sanctions-regime-divergence tracker, where its structural significance is currently assessed rather than established.

Adjacent to both tracks, the FATF grey-list additions of Bosnia and Herzegovina and Iraq at the June 2026 Plenary, following Kuwait and Papua New Guinea in February 2026, register as a listing-tempo data point rather than a sanctions-architecture development in the strict sense; grey-listing operates as an enhanced-due-diligence instrument distinct from the designation regimes OFAC and OFSI use. The incoming FATF presidency of Giles Thomson of the United Kingdom from 1 July 2026 is a governance transition worth continued tracking, since it may bear on future listing tempo, though the sample size across Plenary cycles remains too short to draw a trend conclusion.

Jurisdiction-level tracking reinforces this picture: both the United Kingdom and Mexico are recorded with an increasing risk direction this cycle, though for different structural reasons. The UK signal is coded as enforcement-driven and episodic, reflecting the single, as-yet-unverified OFSI action; the Mexico signal is also coded as enforcement-driven, but the underlying huachicol fiscal typology is treated as an established, recurring channel rather than a one-off episode, given the multi-year suspicious-activity-report record behind it. The standing Russian Sanctions-Evasion Architecture tracker has moved to material-change status this cycle specifically because of the OFSI crypto-exchange vector; the Sanctions Regime Divergence tracker, covering the UK, US, and EU jointly, remains at the lower incremental-development threshold, reflecting the still-unconfirmed status of the underlying UK action.

Outlook

The standing item carried forward from the baseline cycle is primary-source verification of the OFSI crypto-exchange designation; this has not yet been resolved and remains the pacing constraint on upgrading the finding beyond assessed confidence. If and when the primary notice is retrieved, the precedent value for VASP-targeted sanctions enforcement under UK autonomous instruments would be substantial, and the domain assessment should be revisited accordingly. On the cartel-finance track, the scale of prior SAR activity behind the CJNG designations continues to suggest further action against correspondent-banking or trade-finance intermediaries is plausible, an orientation for monitoring rather than a forecast. The sanctions-regime-divergence tracker between the United Kingdom, United States, and European Union remains at incremental-development status and will benefit from additional cycles of observation before its trajectory can be characterised with confidence.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

Ireland sits inside the EU AML Package perimeter as a Member State, and the durable structural backdrop against which this cycle beneficial-ownership signal should be read is the three-instrument architecture that package establishes. This cycle, the directly relevant Irish development is the publication of a third National Risk Assessment on money laundering, terrorist financing, and proliferation financing, accompanied by a 30-Point AML/CFT/CPF Action Plan. The plan addresses interconnection of the Irish beneficial-ownership register with the wider EU BORIS system and grants registrars additional data-verification powers under sixth-Directive transposition, both of which speak directly to corporate-transparency posture rather than to sanctions or crypto-specific concerns.

The improving trajectory recorded for this domain reflects genuine structural progress, but it should not be read as implementation having caught up with the underlying legislative timetable. As of the most recent professional-services assessment consulted this cycle, the legislation required to transpose the relevant AMLD6/AMLR provisions into Irish law had not yet been drafted, despite a beneficial-ownership-specific transposition deadline that falls in the third quarter of 2026. This is a gap between policy commitment, evidenced by the National Risk Assessment and Action Plan, and legislative delivery, and it stands as the single most important watch item in the Irish beneficial-ownership picture at present.

Globally, and as standing context rather than a new development this cycle, the EU AML Package that frames this picture is properly understood as three distinct instruments rather than one. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable across Member States without national transposition. The sixth Anti-Money Laundering Directive requires transposition on a per-Member-State basis, and it is this instrument against which the current Irish drafting gap is measured. The AMLA Regulation, Regulation (EU) 2024/1620, establishes the Anti-Money Laundering Authority and, over the coming implementation sequence, shifts a portion of the supervisory perimeter away from purely national competent authorities such as the Central Bank of Ireland toward a hybrid regime combining continued national supervision with direct EU-level supervision of a defined set of high-risk cross-border obliged entities. This structural shift is the durable backdrop against which the beneficial-ownership and corporate-transparency posture of Ireland, and of every other Member State, should be assessed going forward; it is not itself a finding of this cycle but the architecture within which this cycle findings sit.

Read against that backdrop, the Irish transposition gap takes on additional significance. The AML Regulation is assessed for full application in the third quarter of 2027, and the AMLA direct-supervision perimeter for high-risk obliged entities does not activate until the first quarter of 2028, meaning national beneficial-ownership and verification infrastructure, such as the BORIS interconnection currently being built in Ireland, remains the primary supervisory layer for a further sequence of cycles even as the supranational structure comes online in parallel. The Irish Action Plan, in this sense, is best read as preparatory positioning ahead of a supervisory perimeter that will only partially and gradually shift toward Brussels-level oversight.

The National Risk Assessment also engages FATF Recommendations 24 and 25 on beneficial-ownership transparency for legal persons and arrangements, reflecting the international standard against which both the national assessment and the EU instruments are calibrated. This alignment matters analytically because it means the Irish domestic reform trajectory is not an isolated national exercise but one explicitly designed to satisfy an international as well as an EU-level transparency benchmark, reducing though not eliminating the risk that transposition delay translates into a FATF-relevant deficiency finding in the near term. The fund-structure customer typology flagged in the National Risk Assessment this cycle is a further point of continuity with the corporate-transparency remit specifically, distinguishing this domain finding from the crypto-asset and sanctions-evasion developments recorded elsewhere in the same reporting cycle; fund and corporate-vehicle opacity, rather than virtual-asset infrastructure, is the structural concern the National Risk Assessment and Action Plan are aimed at addressing.

Outlook

The transposition timeline in Ireland is the nearest pressure point in this domain for the coming cycle: the gap between the third-quarter-2026 beneficial-ownership deadline and the current absence of drafted transposing legislation should be watched for either acceleration or formal slippage. More broadly, the sequencing of the EU AML Package, direct AML Regulation application in the third quarter of 2027 and AMLA direct supervision only from the first quarter of 2028, means that national beneficial-ownership infrastructure quality, including the BORIS interconnection and registrar verification powers being built under the 30-Point Action Plan, will remain the operative layer of corporate-transparency enforcement for an extended period regardless of supranational developments.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

As the Financial Integrity Monitor begins tracking this domain, the baseline state for beneficial ownership and corporate transparency centres on Ireland, both because Ireland is the subject jurisdiction for this reporting line and because Ireland sits inside the EU AML Package perimeter as a Member State bound by a shared three-instrument architecture. That architecture is the durable structural backdrop against which every cycle beneficial-ownership signal for Ireland, and for the wider EEA, should be read going forward. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable across Member States without national transposition. The sixth Anti-Money Laundering Directive requires transposition on a per-Member-State basis. The AMLA Regulation, Regulation (EU) 2024/1620, establishes the Anti-Money Laundering Authority and, over the coming implementation sequence, shifts a portion of the supervisory perimeter away from purely national competent authorities such as the Central Bank of Ireland toward a hybrid regime combining continued national supervision with direct EU-level supervision of a defined set of high-risk cross-border obliged entities. None of this is a development specific to the current cycle; it is the standing architecture within which Irish and EEA-wide beneficial-ownership developments will continue to be assessed across future cycles.

Against that backdrop, the first substantive Irish development on record in this tracking line is the publication of a third National Risk Assessment on money laundering, terrorist financing, and proliferation financing, accompanied by a 30-Point AML/CFT/CPF Action Plan. The plan addresses interconnection of the Irish beneficial-ownership register with the wider EU BORIS system and grants registrars additional data-verification powers under sixth-Directive transposition. The domain trajectory is accordingly recorded as improving at this baseline point, reflecting genuine structural commitment, though the cumulative record also carries a clear qualification from the outset: as of the most recent professional-services assessment available this cycle, the legislation required to transpose the relevant AMLD6/AMLR provisions into Irish law had not yet been drafted, despite a beneficial-ownership-specific transposition deadline falling in the third quarter of 2026. This gap between policy commitment and legislative delivery is the central watch item carried forward into subsequent cycles.

Sequencing matters for how this gap should be read. The AML Regulation is assessed for full application in the third quarter of 2027, and the AMLA direct-supervision perimeter for high-risk obliged entities does not activate until the first quarter of 2028. This means that, for a considerable stretch of the tracking period ahead, national beneficial-ownership and verification infrastructure, principally the BORIS interconnection and the additional registrar powers being built in Ireland under the current Action Plan, will remain the primary supervisory layer even as the supranational structure comes progressively online. The Irish Action Plan, read cumulatively, is best understood as preparatory positioning for a supervisory perimeter that will only partially and gradually shift toward Brussels-level oversight over a multi-year horizon, rather than a response to an immediate supranational supervisory obligation.

The National Risk Assessment also engages FATF Recommendations 24 and 25 on beneficial-ownership transparency for legal persons and arrangements, situating the Irish reform trajectory within an international as well as an EU-level transparency benchmark. This dual alignment somewhat reduces, though does not eliminate, the risk that transposition delay translates into a FATF-relevant deficiency finding in the near term, and it is a point worth carrying forward as a structural feature of how the Irish domestic reform is externally validated. The fund-structure customer typology flagged in the current National Risk Assessment is a further point of continuity worth preserving in the cumulative record, distinguishing the corporate-transparency concern, fund and corporate-vehicle opacity, from the crypto-asset and sanctions-evasion developments tracked elsewhere in the same reporting cycle and likely to recur as a distinguishing feature of this domain relative to D1 and D5.

This domain also carries a standing cross-monitor linkage to ESA, whose EU-regulatory-gap remit tracks the same package-level transposition consistency question from a bloc-wide perspective; as the cumulative record for this Irish-focused domain develops, transposition-pace comparisons against other Member States tracked by ESA are likely to become a recurring feature of the analysis, though no such comparative finding is available to report as of the current cycle.

Outlook

Carried forward as the standing watch item, the transposition timeline in Ireland is the nearest pressure point in this domain: the gap between the third-quarter-2026 beneficial-ownership deadline and the current absence of drafted transposing legislation should be tracked across subsequent cycles for either acceleration or formal slippage, and any resolution, in either direction, should be treated as a material domain-level event when it occurs. More broadly, the multi-year sequencing of the EU AML Package, direct AML Regulation application in the third quarter of 2027 and AMLA direct supervision only from the first quarter of 2028, means that national beneficial-ownership infrastructure quality will remain the operative enforcement layer for corporate transparency in Ireland for an extended period, and this cumulative synthesis will continue to track the pace of national implementation against that supranational backdrop as further cycles accrete.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The clearest enabler-jurisdiction signal this cycle comes from Southeast Asia, where two distinct but related casino-based laundering ecosystems are both flagged. The Governor of the National Bank of Cambodia, Chea Serey, issued a public warning that Cambodia risks a third FATF grey-list placement, citing casino- and scam-centre-linked laundering as the driving concern. This claim is corroborated across multiple Tier-3 and Tier-4 sources, though no Tier-1 confirmation of an actual re-listing decision has been located this cycle; the jurisdiction-risk tracker codes Cambodia risk direction as increasing and its enforcement-versus-enablement posture as a capacity deficit rather than a deliberate policy choice, and the underlying dynamic is assessed as structural rather than episodic, meaning the risk factors driving potential re-listing are embedded in the jurisdiction financial-sector architecture rather than tied to a single event.

Laos presents a starker case. It remains confirmed on the FATF grey list, a status in place since 21 February 2025, and the Kings Romans Casino in the Golden Triangle Special Economic Zone persists as a documented trade-based-money-laundering hub. What elevates this from an ordinary enforcement-gap finding to a structural one is the ownership detail: the government of Laos holds a 20 percent equity stake in the sanctioned casino operator. This is coded in the jurisdiction-risk tracker as an enablement posture rather than a capacity deficit, and the structural-versus-episodic classification is structural. In FIM analytical terms, this is the more analytically significant of the two Southeast Asian findings precisely because state equity participation removes any ambiguity about whether the laundering activity persists due to lack of capacity or due to state interest in its continuation; enforcement absence in a jurisdiction with a documented ownership stake in the laundering vehicle is itself a signal, not merely an absence of signal.

The FATF grey-list additions at the June 2026 Plenary, Bosnia and Herzegovina and Iraq, following Kuwait and Papua New Guinea in February 2026, extend the enabler-jurisdiction watch list geographically beyond Southeast Asia into the Balkans and the Middle East, and both new entrants are coded in the jurisdiction-risk tracker with a capacity-deficit rather than enablement classification, distinguishing them structurally from the Laos case even though all four sit within the same formal FATF listing category. This distinction, capacity deficit versus deliberate enablement, is the analytical fault line running through the enabler-jurisdiction domain this cycle, and it argues against treating all grey-listed jurisdictions as equivalent risk profiles simply because they share a listing status.

Colombia, by contrast, illustrates a jurisdiction where the standing enhanced-follow-up status under GAFILAT produced no fresh signal this cycle, a stable data point that is itself worth recording precisely because it contrasts with the escalating postures documented for Cambodia and the Balkan and Middle Eastern new entrants.

Applying the enabler-jurisdiction filter across all four cases surfaces a consistent question set: legal framework adequacy, enforcement follow-through, and the distinction between capacity constraint and deliberate policy choice. Cambodia and the two newly listed jurisdictions register primarily on the capacity axis, where the FATF grey-list mechanism functions as a corrective pressure intended to mobilise domestic reform. Laos registers on the choice axis, where the state equity stake in the sanctioned operator suggests the relevant constraint is political rather than technical, a distinction with material implications for how quickly, or whether, remediation should be expected in each case.

Outlook

Cambodia second National Risk Assessment, reported as underway with illegal online gambling flagged as a specific area of concern, is the item most likely to produce a material development in this domain over the coming cycles; a formal FATF decision on re-listing, if it occurs, would be a significant escalation from the current warning-stage posture. For Laos, the state-equity dynamic in the Golden Triangle Special Economic Zone is unlikely to resolve quickly given its structural rather than episodic character, and continued absence of enforcement action against the casino operator should itself be read as a data point on enablement rather than treated as a null finding. The newly listed Balkan and Middle Eastern jurisdictions warrant monitoring for whether their capacity-deficit classification shifts toward either remediation or entrenchment over subsequent Plenary cycles.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

At the baseline point where the Financial Integrity Monitor begins tracking this domain, the enabler-jurisdiction picture is dominated by two distinct casino-based laundering ecosystems in Southeast Asia, with a secondary and geographically broader signal from the FATF grey-list process. The Governor of the National Bank of Cambodia, Chea Serey, has issued a public warning that Cambodia risks a third FATF grey-list placement, citing casino- and scam-centre-linked laundering. This is corroborated across multiple Tier-3 and Tier-4 sources without Tier-1 confirmation of an actual re-listing decision, and the jurisdiction-risk tracker codes Cambodia as an increasing-risk jurisdiction where the underlying enforcement-versus-enablement posture is a capacity deficit rather than a deliberate policy choice, with the structural-versus-episodic classification recorded as structural. This baseline classification, capacity deficit rather than deliberate enablement, is the frame that should govern how future Cambodia developments are read: a formal re-listing decision, if it occurs, would represent an escalation within a persistent structural pattern rather than a new phenomenon.

Laos represents the more analytically severe baseline case in this domain. It remains confirmed on the FATF grey list, a status in place since 21 February 2025, and the Kings Romans Casino in the Golden Triangle Special Economic Zone persists as a documented trade-based-money-laundering hub. The detail that elevates this from an ordinary enforcement gap to a structural finding, and that should anchor the cumulative record for this jurisdiction going forward, is that the government of Laos holds a 20 percent equity stake in the sanctioned casino operator. This is coded as an enablement rather than capacity-deficit posture, and as structural rather than episodic. The analytical baseline established here, that state equity participation removes ambiguity about whether laundering persists due to lack of capacity or due to state interest in its continuation, should be treated as a standing interpretive lens for this jurisdiction across all future cycles, absent a material change such as divestment or a change in ownership structure.

The FATF grey-list additions at the June 2026 Plenary, Bosnia and Herzegovina and Iraq, alongside Kuwait and Papua New Guinea from February 2026, extend the geographic scope of the enabler-jurisdiction watch list beyond Southeast Asia for the first time in this tracking record, into the Balkans and the Middle East. All four new entrants are coded with a capacity-deficit rather than enablement classification, a structural distinction from Laos that is worth preserving as new jurisdictions are added to this domain scope in future cycles: shared grey-list status does not imply a shared underlying risk architecture, and the capacity-deficit-versus-enablement axis established in this baseline cycle is the analytical tool this monitor will continue to apply to distinguish them.

Colombia, held in the enhanced follow-up process administered by GAFILAT with no fresh signal this cycle, establishes a useful contrast case at the other end of the trajectory spectrum: a jurisdiction under standing international scrutiny that has not generated a fresh escalation signal, distinguishing it from the actively deteriorating postures recorded for Cambodia and the newly listed jurisdictions.

Applying the enabler-jurisdiction filter consistently across this baseline record surfaces three recurring questions that this monitor will carry into future cycles for every jurisdiction added to this domain: the adequacy of the legal framework, the degree of enforcement follow-through, and whether the underlying constraint on remediation is a matter of capacity or of jurisdictional choice. This three-part framework should be treated as the standing analytical spine for the Enabler Jurisdictions and Professional Facilitators domain, with Laos as the current reference case for the choice end of the spectrum and Cambodia, Bosnia and Herzegovina, Iraq, Kuwait, and Papua New Guinea currently populating the capacity end.

Outlook

Carried forward from this baseline cycle, the most consequential near-term watch item is the second National Risk Assessment reported as underway in Cambodia, with illegal online gambling flagged as a specific area of concern; a formal FATF decision on re-listing, should it occur in a subsequent cycle, would represent a material escalation from the current warning-stage posture and should be assessed against this baseline. For Laos, the state-equity dynamic in the Golden Triangle Special Economic Zone is unlikely to resolve quickly given its structural character, and continued absence of enforcement action against the casino operator should itself continue to be read as a data point on enablement in subsequent cycles rather than as a null finding. The newly listed Balkan and Middle Eastern jurisdictions warrant sustained monitoring across coming cycles for whether their capacity-deficit classification shifts toward remediation or entrenchment.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

No substantive finding was located in the conflict-finance and extractive-industry-integrity domain this cycle. The domain tracker records a stable trajectory with an explicit note that this reflects the absence of a supported development rather than an assessed judgment that risk in this space has genuinely stabilised; no confidence rating is attached to this domain this cycle for that reason. The interpreter gaps register explicitly logs this as a coverage gap: research this cycle did not surface material on Sahel conflict-mineral flows, Democratic Republic of Congo mining-sector governance, or other conflict-finance channels that have featured in the standing scope of this domain. Consistent with the honesty-over-coverage principle governing this brief, this gap is recorded plainly rather than filled with unsupported material or inferred from adjacent findings.

It is worth noting, in the interest of architecture-over-incident framing, that the absence of a finding in this domain this cycle should not be read as an absence of activity in the underlying subject matter; it is a research-coverage limitation specific to this cycle sources searched, and the coverage-gaps register flags Sub-Saharan Africa and Central Asia jurisdictions specifically as not surfaced with fresh material this cycle. The cross-monitor relevance of this domain to SCEM, on conflict finance specifically, and to ERM, on commodity-flow evasion, means that any future finding here is likely to carry immediate propagation value to both adjacent monitors; this is noted as a standing structural expectation rather than as a claim about this cycle content.

Outlook

This domain is flagged for prioritised coverage in the coming research cycle, particularly for Sahel conflict-mineral flows and Democratic Republic of Congo mining-sector governance, both of which sit within the standing scope of this domain but were not populated this cycle. Until fresh material is retrieved, this domain sub-brief will continue to be issued with a limited-signal flag rather than padded content.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity — Cumulative Analysis

At this baseline cycle, the Financial Integrity Monitor cumulative record for conflict finance and extractive-industry integrity opens with an explicit absence rather than a substantive finding. No material on Sahel conflict-mineral flows, Democratic Republic of Congo mining-sector governance, or other conflict-finance channels within the standing scope of this domain was surfaced by research this cycle, and the domain tracker records a stable trajectory with no confidence rating attached, reflecting the fact that this reflects a coverage gap rather than an assessed judgment that underlying risk has stabilised. Consistent with the honesty-over-coverage principle that governs this monitor cumulative synthesis, this absence is recorded plainly at the outset of the tracking record rather than inferred or filled with unsupported material drawn from adjacent domains or general knowledge.

This domain carries standing cross-monitor relevance to SCEM on conflict finance specifically and to ERM on commodity-flow evasion, and any future finding populated into this domain is likely to carry immediate propagation value to both. This expectation is recorded now as a structural feature of the domain design, established before any substantive finding has been logged, so that future cycles can be read against this explicit baseline of absence rather than against an assumption of prior coverage that did not in fact occur.

Outlook

This domain is flagged for prioritised research coverage in coming cycles, particularly Sahel conflict-mineral flows and Democratic Republic of Congo mining-sector governance. Until fresh, sourced material is retrieved, this cumulative synthesis will continue to be issued short and flagged for limited signal, in preference to padding the record with unsupported content, consistent with the standing honesty-over-coverage guardrail applied throughout this monitor.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The most consequential crypto-sector development directly relevant to Ireland regulatory perimeter this cycle is the fine imposed by the Central Bank of Ireland on Coinbase Europe Limited: 21,464,734 euro for anti-money-laundering and counter-terrorist-financing transaction-monitoring failures spanning 2021 through 2025. This is held at high confidence, resting on a primary Central Bank of Ireland press release, and it stands as one of the largest AML enforcement actions taken against a crypto-asset firm by any EU national competent authority to date. The finding maps directly onto FATF Recommendation 15 on virtual assets and virtual-asset service providers, and it is coded against the VASP-counterparty customer typology, situating it squarely within the crypto-integrity remit of this domain rather than as a general AML enforcement action incidental to the sector.

Running in parallel, and directly bearing on the same Irish crypto-asset population, the national grandfathering window allowing VASPs registered in Ireland to transition to CASP status under Article 143(3) of the Markets in Crypto-Assets Regulation closes on 1 July 2026, with mandatory Central Bank of Ireland portal submission required from 2 April 2026. This is the operative near-term regulatory deadline for every crypto-asset operator currently active in the Irish market under legacy national VASP registration; sources consulted this cycle conflict on whether Ireland compressed the standard eighteen-month EU-wide transition window relative to other Member States, and this discrepancy has not been resolved. Regardless of the precise window length, the structural effect is the same: unauthorised crypto-asset service provision to EU clients becomes unlawful once the grandfathering period closes, and firms operating under the legacy national regime must complete full authorisation or exit the market.

Read together, these two Irish developments describe a crypto-sector supervisory environment in transition. The Coinbase Europe enforcement action demonstrates that the current national supervisory regime, operating ahead of full MiCA implementation, retains real enforcement capacity and has exercised it at a scale that signals seriousness of intent. The MiCA CASP grandfathering closure signals that this national-level supervisory phase is itself time-limited, folding into a harmonised EU-wide authorisation regime by mid-2026. The Coinbase fine, in this sense, may be read as one of the last major enforcement actions of the pre-MiCA national supervisory era in Ireland rather than as an indicator of what post-MiCA supervision will look like once CASPs are directly and fully within scope of the AML Regulation, which formally adds CASPs as obliged entities and lowers the occasional-transaction customer-due-diligence threshold to 1,000 euro specifically for this sector.

Globally, this cycle crypto-integrity picture also sits against the broader MiCA transition occurring across the EU simultaneously, though the specific Irish supervisory portal-submission mechanics and enforcement track record are the directly relevant developments for firms and counterparties operating in or through the Irish market, rather than the EU-wide MiCA rollout considered in the abstract. This domain also intersects directly with the sanctions-architecture developments recorded elsewhere this cycle: the first-ever application by OFSI of Regulation 17A(2) against crypto-asset exchanges illustrates that virtual-asset infrastructure is simultaneously a sanctions-evasion concern and an AML-supervision concern, and firms operating in the Irish market under the MiCA transition will need to satisfy both regulatory lenses as full CASP authorisation approaches, even though the OFSI finding itself remains at assessed rather than confirmed status pending primary-source verification.

Outlook

The near-term watch item is straightforward and time-bound: the 1 July 2026 MiCA CASP grandfathering closure will determine which currently operating Irish crypto-asset firms transition successfully to full authorisation and which do not, and any enforcement or wind-down activity following that date is likely to be the next material development in this domain. The unresolved question of whether Ireland compressed its transition window relative to the EU-wide standard should also be resolved with a primary-source citation in a subsequent cycle. Beyond the immediate transition, the Coinbase Europe enforcement action sets a quantified benchmark for transaction-monitoring failure penalties in the Irish crypto sector, and subsequent enforcement actions, if any, are likely to be assessed against this figure as a reference point for either escalation or moderation in supervisory posture.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

The baseline record for the crypto, digital-assets, and financial-innovation domain, as tracked for the Irish subject jurisdiction, opens with two developments that together describe a supervisory regime in active transition. The first is the fine imposed by the Central Bank of Ireland on Coinbase Europe Limited, 21,464,734 euro for anti-money-laundering and counter-terrorist-financing transaction-monitoring failures spanning 2021 through 2025, held at high confidence on primary regulatory sourcing and standing as one of the largest crypto-sector AML enforcement actions taken by any EU national competent authority to date. The second is the closure of the national grandfathering window allowing Ireland-registered VASPs to transition to CASP status under Article 143(3) of the Markets in Crypto-Assets Regulation, which falls on 1 July 2026, with mandatory Central Bank of Ireland portal submission required from 2 April 2026.

Read as a pair, and as the frame that should anchor this domain cumulative record going forward, these two developments describe the final phase of a national, pre-harmonised crypto-supervisory regime in Ireland giving way to a fully harmonised EU-wide authorisation and supervision framework. The Coinbase Europe enforcement action should be understood, in this cumulative context, as one of the last major enforcement actions of the pre-MiCA national supervisory era rather than as representative of what post-MiCA supervision will look like once crypto-asset service providers are formally and fully within scope of the AML Regulation as obliged entities, with a lowered occasional-transaction customer-due-diligence threshold of 1,000 euro specifically applied to this sector. This distinction, pre-transition enforcement benchmark versus post-transition supervisory model, is the central interpretive lens this monitor will carry forward for the Irish crypto-integrity domain.

An unresolved sourcing question, whether Ireland compressed the standard eighteen-month EU-wide MiCA transition window relative to other Member States, remains open at this baseline point and should be treated as a standing item for resolution in subsequent cycles; regardless of its resolution, the structural effect of the 1 July 2026 deadline, that unauthorised crypto-asset service provision to EU clients becomes unlawful once the grandfathering period closes, is not in question and is the operative fact around which firms currently operating in the Irish market must plan.

This domain also carries a standing cross-domain linkage established at this baseline cycle: the first-ever application by OFSI of Regulation 17A(2) against eighteen crypto-asset exchanges illustrates that virtual-asset infrastructure is simultaneously a sanctions-evasion concern, tracked under the Sanctions Architecture and Evasion domain, and an AML-supervision concern tracked here. Firms transitioning to full CASP authorisation in Ireland will need to satisfy both regulatory lenses simultaneously, and this dual exposure is a structural feature of the crypto-integrity domain that this monitor expects to recur as a cross-domain theme in future cycles, even though the OFSI finding itself remains at assessed rather than confirmed status pending primary-source verification.

The source-quality profile underlying this domain baseline is comparatively strong relative to other domains tracked this cycle: the Irish jurisdiction record shows a national primary source, an institutional primary source, and a source count meeting the monitor floor threshold, giving the Coinbase Europe and MiCA transition findings a firmer evidentiary basis than, for instance, the still-unverified OFSI crypto-exchange sanctions finding tracked under the Sanctions Architecture domain. This asymmetry in evidentiary strength across domains sharing a common Irish jurisdictional focus is itself a feature worth carrying into future cumulative synthesis, since it affects how confidently cross-domain crypto-related findings can be combined into a single risk narrative for firms operating in the Irish market.

Outlook

The most consequential near-term event carried forward from this baseline cycle is the 1 July 2026 MiCA CASP grandfathering closure, which will determine which currently operating Irish crypto-asset firms transition successfully to full authorisation and which do not; enforcement or wind-down activity following that date is expected to be the next material development in this domain and should be assessed against the Coinbase Europe fine as a quantified benchmark for transaction-monitoring failure penalties. The unresolved question of whether Ireland compressed its transition window should also be resolved with a primary-source citation in a subsequent cycle, and this monitor will continue to track that resolution as a standing open item in this cumulative record.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The Compliance Technology and Active Defence domain carries a watch-level trajectory this cycle, anchored in a single indirect signal rather than a fresh, dedicated finding. The Central Bank of Ireland fine against Coinbase Europe Limited, for anti-money-laundering and counter-terrorist-financing transaction-monitoring failures between 2021 and 2025, functions as a baseline compliance-technology gap indicator for this domain: a transaction-monitoring failure of this scale and duration, at a firm operating in a well-regulated jurisdiction, illustrates a persistent gap between supervisory expectations for automated monitoring capability and documented industry practice. No fresh, cycle-specific FinCEN or FCA compliance-technology guidance citation was located this cycle to update this domain further, and this absence is logged explicitly as a coverage gap rather than inferred or filled with unsupported material.

The timing of this baseline indicator is analytically relevant given the approaching MiCA CASP authorisation deadline of 1 July 2026: firms currently transitioning from national VASP registration to full CASP status will be assessed, at least in part, against transaction-monitoring adequacy standards of the kind the Coinbase Europe enforcement action shows can fail even under an established national supervisory regime.

Outlook

This domain is flagged for closer coverage in coming cycles, specifically for fresh regulatory guidance on AI- or machine-learning-based transaction-monitoring expectations from FinCEN, the FCA, or EU-level supervisors, none of which were located this cycle. Until such material is retrieved, this sub-brief will continue to carry a limited-signal flag rather than be padded with unsupported content.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

The baseline record for the compliance-technology and active-defence domain rests, at this cycle, on a single indirect indicator rather than a dedicated finding: the fine imposed by the Central Bank of Ireland on Coinbase Europe Limited for anti-money-laundering and counter-terrorist-financing transaction-monitoring failures between 2021 and 2025. Read cumulatively, this stands as the reference baseline for a persistent gap between supervisory expectations for automated transaction-monitoring capability and documented industry practice, observed in a firm operating within a well-regulated jurisdiction rather than in a permissive one, which sharpens rather than dilutes its significance as a compliance-technology signal. No fresh, cycle-specific FinCEN or FCA compliance-technology guidance citation was located this cycle to extend this baseline further, and this absence is logged explicitly as a coverage gap.

The approaching MiCA CASP authorisation deadline of 1 July 2026 gives this baseline indicator forward relevance: firms transitioning from national VASP registration to full CASP status in Ireland will be assessed, at least in part, against transaction-monitoring adequacy standards of the kind the Coinbase Europe action shows can fail even under an established national supervisory regime, and this monitor expects the domain record to be populated further as post-transition supervisory practice becomes observable in coming cycles.

Outlook

This domain remains flagged for closer coverage going forward, specifically for regulatory guidance on AI- or machine-learning-based transaction-monitoring expectations from FinCEN, the FCA, or EU-level supervisors, none of which were located this cycle. Until such material is retrieved, this cumulative synthesis will continue to carry a limited-signal flag rather than be extended with unsupported content, in keeping with the honesty-over-coverage principle applied throughout this monitor.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
Consultation2026-Q3 · ±quarter

AMLD6 beneficial-ownership transposition deadline

Irish BO registrars gain additional data-verification powers; BORIS interconnection continues ahead of full AMLD6 transposition by July 2027.
In Force Pending2026-Q3 · ±quarter

MiCA CASP grandfathering closure

Unauthorised crypto-asset service provision to EU clients becomes unlawful; firms must complete full CASP authorisation or wind down.
In Force Pending2027-Q3 · ±half_year

EU AMLR (Regulation 2024/1624) full application

Directly-applicable uniform AML/CFT rulebook replaces national transpositions; CASPs formally added as obliged entities; occasional-transaction CDD threshold lowered to EUR 10,000 (EUR 1,000 for CASPs).
In Force Pending2028-Q1 · ±year

AMLA direct supervision of high-risk obliged entities

A new supranational supervisor assumes direct oversight of designated high-risk obliged entities.
Proposed2028-Q3 · ±multi_year

EU SNRA refresh cycle change under 6AMLD

Supra-national risk assessment cadence lengthens from 2 to 4 years but scope broadens.
5 dated · 4 pending date · baseline fim-2026-07-10
Role action cards
MLROHigh

OFAC and FinCEN escalated action against the CJNG fuel-smuggling network while the Central Bank of Ireland fined Coinbase Europe for transaction-monitoring failures, both bearing on reporting and screening obligations this cycle.

The CJNG designations and the accompanying FinCEN supplemental alert extend SAR-relevant typology guidance for trade-finance and correspondent-banking exposure tied to fuel-smuggling and tax-evasion schemes. The Coinbase Europe fine, for AML and CTF transaction-monitoring failures between 2021 and 2025, illustrates a documented monitoring-control gap directly relevant to reportable-activity threshold design in crypto-asset-adjacent business. The National Risk Assessment published by Ireland also updates the sixth-Directive beneficial-ownership verification landscape relevant to customer due diligence.

4 evidence refs
ComplianceHigh

Irish National Risk Assessment publication, the MiCA CASP grandfathering closure, elevated Southeast Asian jurisdictional risk, and FATF grey-list expansion collectively update the obliged-entity and jurisdictional-exposure landscape this cycle.

The third National Risk Assessment and 30-Point Action Plan published by Ireland update beneficial-ownership verification and BORIS interconnection expectations, though transposing legislation had not yet been drafted as of the latest assessment. The MiCA CASP grandfathering closure on 1 July 2026 is a hard deadline for crypto-asset operators currently under national VASP registration. The public re-listing risk warning issued in Cambodia and the confirmed grey-list status of Laos both bear on enhanced-due-diligence posture for counterparties linked to those jurisdictions, as does the FATF grey-list expansion to include Bosnia and Herzegovina, Iraq, Kuwait, and Papua New Guinea. The Coinbase Europe fine illustrates a documented control-framework failure at scale.

7 evidence refs
LegalHigh

The first-ever application by OFSI of Regulation 17A(2) against crypto-asset exchanges, the OFAC CJNG designations, the FATF grey-list expansion, and the MiCA CASP transition deadline together raise liability-exposure and enforcement-trajectory questions this cycle.

The OFSI crypto-exchange designation, if confirmed by a primary notice, would establish a new UK enforcement mechanism against virtual-asset infrastructure with direct sanctions-nexus liability implications for exchanges and their counterparties. The OFAC CJNG designations and the FATF grey-list expansion both extend sanctions and enhanced-due-diligence exposure for entities with counterparty links to the newly designated or listed jurisdictions and networks. The MiCA CASP grandfathering deadline of 1 July 2026 creates a hard compliance cutoff with direct client-instruction implications for crypto-asset operators currently under national registration in Ireland.

6 evidence refs
BoardHigh

A EUR 21.46 million AML enforcement fine against Coinbase Europe, a third National Risk Assessment published by Ireland, and a novel UK crypto-exchange sanctions mechanism together signal material financial-crime and reputational exposure this cycle.

The Coinbase Europe fine represents one of the largest crypto-sector AML enforcement actions taken by an EU national competent authority to date, a scale relevant to institutional reputational and financial exposure. The National Risk Assessment and Action Plan published by Ireland signal a structurally improving national AML posture, though the gap between commitment and drafted transposing legislation is a governance-relevant timeline risk. The first-ever application by OFSI of Regulation 17A(2) to crypto-asset exchanges, while still assessed rather than confirmed, signals a potential widening of the sanctions-enforcement perimeter relevant to institutions with virtual-asset exposure.

3 evidence refs
CTOHigh

The novel OFSI crypto-exchange sanctions mechanism, the Coinbase Europe transaction-monitoring fine, and the MiCA CASP transition deadline together bear on digital-asset infrastructure and platform-architecture risk this cycle.

The first-ever application by OFSI of Regulation 17A(2) against eighteen crypto-asset exchanges signals that virtual-asset infrastructure itself, not only downstream designated persons, is now a direct sanctions-enforcement target, a technical evasion-vector consideration for platform architecture. The Coinbase Europe fine for transaction-monitoring failures is a documented instance of monitoring-technology inadequacy at scale. The MiCA CASP grandfathering closure on 1 July 2026 creates a hard technical and governance-authorisation deadline for crypto-asset platforms currently operating in Ireland under national VASP registration.

3 evidence refs
RiskHigh

Elevated re-listing risk in Cambodia, confirmed grey-list persistence in Laos, escalating cartel fuel-smuggling designations, and the FATF grey-list expansion together concentrate enabler-jurisdiction and typology risk this cycle.

The public warning issued by the Governor of the National Bank of Cambodia and the confirmed grey-list status of Laos, anchored in a documented state-equity stake in a sanctioned casino operator, both represent structural rather than episodic enabler-jurisdiction risk concentration. The OFAC and FinCEN escalation against the CJNG fuel-smuggling network represents an emerging trade-based-money-laundering typology with cross-border correspondent-banking exposure. The FATF grey-list expansion to Bosnia and Herzegovina, Iraq, Kuwait, and Papua New Guinea broadens the geographic footprint of jurisdictions requiring enhanced monitoring.

5 evidence refs
OperationsHigh

CJNG-related designations, the FinCEN supplemental alert, the Coinbase Europe transaction-monitoring fine, and the MiCA CASP transition deadline together carry process-level screening and monitoring implications this cycle.

The OFAC designations and FinCEN supplemental alert on the CJNG fuel-smuggling network are directly relevant to screening-list updates and transaction-monitoring rule tuning for trade-finance and correspondent-banking workflows. The Coinbase Europe fine illustrates a documented failure of transaction-monitoring processes over a multi-year period. The MiCA CASP grandfathering closure on 1 July 2026 is a process-level deadline requiring completed authorisation workflows for crypto-asset operators currently under national registration in Ireland.

4 evidence refs
AuditHigh

The Coinbase Europe transaction-monitoring fine, the National Risk Assessment published by Ireland, and the MiCA CASP transition deadline together raise control-testing and documentation-adequacy questions this cycle.

The multi-year duration of the transaction-monitoring failures underlying the Coinbase Europe fine, from 2021 through 2025, raises questions about the adequacy of control-testing scope and audit-trail review over that period. The National Risk Assessment and Action Plan published by Ireland document the current state of national AML/CFT/CPF control architecture and are a relevant reference for internal control-framework benchmarking. The MiCA CASP grandfathering closure creates a discrete authorisation milestone against which documentation completeness can be tested.

3 evidence refs
Decision lens
MLRO

OFAC and FinCEN escalated action against the CJNG fuel-smuggling network while the Central Bank of Ireland fined Coinbase Europe for transaction-monitoring failures, both bearing on reporting and screening obligations this cycle.

Compliance

Irish National Risk Assessment publication, the MiCA CASP grandfathering closure, elevated Southeast Asian jurisdictional risk, and FATF grey-list expansion collectively update the obliged-entity and jurisdictional-exposure landscape this cycle.

Legal

The first-ever application by OFSI of Regulation 17A(2) against crypto-asset exchanges, the OFAC CJNG designations, the FATF grey-list expansion, and the MiCA CASP transition deadline together raise liability-exposure and enforcement-trajectory questions this cycle.

Board

A EUR 21.46 million AML enforcement fine against Coinbase Europe, a third National Risk Assessment published by Ireland, and a novel UK crypto-exchange sanctions mechanism together signal material financial-crime and reputational exposure this cycle.

CTO

The novel OFSI crypto-exchange sanctions mechanism, the Coinbase Europe transaction-monitoring fine, and the MiCA CASP transition deadline together bear on digital-asset infrastructure and platform-architecture risk this cycle.

Risk

Elevated re-listing risk in Cambodia, confirmed grey-list persistence in Laos, escalating cartel fuel-smuggling designations, and the FATF grey-list expansion together concentrate enabler-jurisdiction and typology risk this cycle.

Operations

CJNG-related designations, the FinCEN supplemental alert, the Coinbase Europe transaction-monitoring fine, and the MiCA CASP transition deadline together carry process-level screening and monitoring implications this cycle.

Audit

The Coinbase Europe transaction-monitoring fine, the National Risk Assessment published by Ireland, and the MiCA CASP transition deadline together raise control-testing and documentation-adequacy questions this cycle.

Shared evidence: 9 refs
Typology observations
Exposure: {'total_matched_typologies': 0, 'by_typology': {}, 'top_indicators': [], 'exposure_note': None}
Scenario sketches

Illustrative AMLA transition and supervisory-perimeter reshaping

As an illustrative orientation only, consider how the staged move from purely national AML supervision toward the AMLA direct and indirect supervision perimeter, operating alongside the directly applicable AML Regulation and per-state sixth-Directive transposition, could reshape the supervisory and evasion landscape over the coming years. A hypothetical cross-border obliged entity operating across several Member States might, under the pre-AMLA architecture, face inconsistent national supervisory intensity that could be exploited through jurisdiction shopping for the least rigorous national supervisor. As the AMLA direct-supervision perimeter for high-risk cross-border groups activates, this arbitrage surface could narrow structurally, though the multi-year gap between AMLA operational start and the activation of its direct-supervision perimeter means the transitional period itself could remain a window of continued exploitation. This is architecture-over-incident illustration, not a prediction of how any specific entity will behave.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative VASP-infrastructure sanctions-evasion layering

As an illustrative orientation only, consider how a virtual-asset exchange operating across multiple regulatory perimeters could, hypothetically, be used as connective infrastructure for sanctioned-counterparty exposure, with transaction flows structured through intermediary wallets and cross-exchange transfers designed to obscure the ultimate counterparty. If designation practice by an authority such as OFSI begins to target exchange infrastructure directly rather than only downstream designated persons, this could hypothetically alter the calculus for such intermediary structuring by increasing the exposure of the infrastructure layer itself. This is architecture-over-incident illustration only, not an assertion about the eighteen-exchange designation currently under primary-source verification, and not a prediction of future enforcement behaviour.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturematerial_changeOFSI's first-ever application of Reg 17A(2) to crypto-exchanges (18 entities incl. HTX, 26 May 2026) extends the Russia sanctions-evasion enforcement architecture into VASP rails.
T2 · EU AML Package / AMLAmaterial_changeAMLR on track for full application; AMLD6 requires BO-register-specific transposition by July 2026; Ireland's third NRA and 30-Point Action Plan published, transposing legislation not yet drafted per most recent assessment.
T3 · FATF Grey Listmaterial_changeJune 2026 Plenary added Bosnia and Herzegovina and Iraq; February 2026 Plenary added Kuwait and Papua New Guinea. Laos remains grey-listed; Cambodia at elevated re-listing risk but not currently listed.
T4 · Beneficial-Ownership Register Statusmaterial_changeIreland's registrars gain additional data-verification powers following AMLD6 transposition; BORIS interconnection work ongoing.
T5 · Crypto and Digital-Asset Integritymaterial_changeMiCA VASP-to-CASP grandfathering closes EU-wide 1 July 2026; CBI's EUR 21.46m Coinbase Europe fine stands as a baseline crypto-sector enforcement marker ahead of full MiCA supervision.
T6 · Sanctions Regime Divergenceincremental_developmentUK OFSI's first-time crypto-exchange designation under an autonomous UK sanctions instrument illustrates continuing UK-EU-US divergence in designation mechanics, though confirmation against a primary OFSI notice is pending.
Registers

Enforcement actions

  • Coordinated arrests and cash seizures spanning Newry (Northern Ireland) and the Republic of Ireland; two men arrested by An Garda Síochána with a further search seizing £176,000, connected to an earlier Newry seizure of approximately €450,000 and £258,000. 28 May 2026
  • Following the OCCRP investigation, the Irish government confirmed it was examining reports that alumina from the Aughinish refinery was reaching Russian smelters supplying EU-sanctioned arms manufacturers; the issue was raised in the Oireachtas and by the Taoiseach. 24 Mar 2026
  • The European Commission opened an infringement procedure against Ireland (alongside France and Latvia) for incorrect transposition of the 4th and 5th Anti-Money Laundering Directives, specifically citing inadequacy and inaccessibility of Ireland's beneficial ownership register of trusts. 24 Apr 2024

Sanctions changes

  • The EU's 19th sanctions package against Russia targeted Russian energy revenues, third-country banks facilitating evasion, and crypto asset service providers, alongside export restrictions on 45 new entities including some in third countries supplying dual-use goods. As an EU member, Ireland implements these measures directly. 23 Oct 2025
  • The EU Council sanctioned 41 additional vessels of Russia's shadow fleet (18 December 2025) and 9 shadow-fleet enablers (15 December 2025), imposing port-access bans and maritime-service restrictions, directly applicable in Ireland as an EU coastal member state with significant port infrastructure. 18 Dec 2025
  • Despite the Aughinish Alumina revelations, no EU sanctions listing has yet been added specifically closing the alumina/aluminium re-export channel; Belgium and several MEPs are lobbying the Commission to expand the sanctions regime, while the Irish government's own review remains open, illustrating a live gap between the sanctions regime's letter and its intended strategic effect. 24 Mar 2026

Regulatory horizon (register)

  • MiCA transitional period closes for crypto asset service providers
  • AML Regulation (AMLR) direct-applicability start for Ireland
  • AMLA direct/indirect supervisory perimeter build-out affecting Irish entities
  • Ireland's next FATF mutual evaluation (5th round) scheduling

Active schemes

  • [CRITICAL] Irish alumina refinery feeding sanctioned Russian arms chain
  • [HIGH] Trust and fund-vehicle beneficial ownership opacity
  • VASP-to-CASP transitional crypto compliance gap
  • Cross-border cash recycling by island-of-Ireland organised crime
Sources
  1. FATF
  2. FATF
  3. OCCRP
  4. European Commission Representation in Ireland
  5. Elliptic
  6. Council of the European Union
  7. UK National Crime Agency
  8. European Commission (DG FISMA)
Coverage gaps
Ireland's beneficial ownership register of trusts remains fl…
Ireland's beneficial ownership register of trusts remains flagged by the European Commission as inadequate in completeness and accessibility, an infringement opened in April 2024 that remained unresolved as of this baseline, ahead of the AMLR's directly-applicable BO rules taking effect.
FATF's 2017 Mutual Evaluation found Ireland had secured only…
FATF's 2017 Mutual Evaluation found Ireland had secured only guilty-plea money-laundering convictions with no convictions achieved after a full trial, a gap the 2022 follow-up report did not report as resolved, despite Ireland's status as a major international financial centre.
Despite the scale of the Aughinish Alumina revelations (roug…
Despite the scale of the Aughinish Alumina revelations (roughly $400 million of alumina reaching Russian smelters supplying sanctioned arms makers in 2024 alone), no sanctions listing, penalty, or licence action had been taken against the refinery or its supply chain as of this baseline; only a government review was opened.
The designated authoritative NRA for Ireland (Ireland AML St…
The designated authoritative NRA for Ireland (Ireland AML Steering Committee, National Risk Assessment 2026) could not be directly retrieved and read in full during this research pass; its content is referenced by seed provenance only and requires primary-document verification in the next cycle.
No standalone Central Bank of Ireland AML/CTF enforcement fi…
No standalone Central Bank of Ireland AML/CTF enforcement fine against a regulated financial institution was identified as publicly disclosed within the 18-month baseline window, despite a historical base rate of frequent AML fines (108 since 2006, totalling roughly €57 million) against Irish banks.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.